-
public-pentesting-reports Public
Forked from juliocesarfort/public-pentesting-reportsA list of public penetration test reports published by several consulting firms and academic security groups.
HTML UpdatedJun 6, 2024 -
nacosleak Public
Forked from a1phaboy/nacosleak一键获取nacos中的配置文件信息和绘制密码本
Go MIT License UpdatedAug 31, 2023 -
cve-2022-27255 Public
Forked from infobyte/cve-2022-27255Python GNU General Public License v3.0 UpdatedAug 13, 2022 -
windows-coerced-authentication-methods Public
Forked from p0dalirius/windows-coerced-authentication-methodsA list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.
Python UpdatedJul 7, 2022 -
0day Public
Forked from 0x24bin/0day各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC 该项目将不断更新
C GNU General Public License v3.0 UpdatedMar 30, 2022 -
SharpStay Public
Forked from tothi/SharpStay.NET project for installing Persistence
C# GNU General Public License v3.0 UpdatedFeb 14, 2022 -
port_tunnel Public
Forked from AlphabugX/port_tunnel这个工具只是临时名称,我称他为端口隧道技术,解决隔离内网上线问题。
Go GNU General Public License v3.0 UpdatedJan 20, 2022 -
PentesterSpecialDict Public
Forked from evilc0deooo/PentesterSpecialDict渗透测试人员专用精简化字典 Dictionary for penetration testers happy hacker
Python UpdatedJan 12, 2022 -
-
-
log4jScan_Modify Public
Forked from atlassion/log4jScan_Modify对接JNDIMonitor的Burp Suite被动扫描插件
Java UpdatedDec 16, 2021 -
Small_Log4j2Scan Public
Forked from AkunWin/Log4j2Scan-1一款无须借助dnslog且完全无害的log4j2反连检测工具,解析RMI和LDAP协议实现,可用于甲方内网自查
Go Apache License 2.0 UpdatedDec 16, 2021 -
log4j2burpscanner Public
Forked from Jeromeyoung/log4j2burpscannerCVE-2021-44228,log4j2 burp插件 Java版本,可自定义ceye.io,也可以自定义内网的dnslog平台及请求接口定位内网漏洞机器(log4j2 RCE Burp Suite Passive Scanner,can customize the ceye.io api or other apis,including internal networks)
Java UpdatedDec 15, 2021 -
Log4j2-RCE-Scanner Public
Forked from samy1937/Log4j2-RCE-ScannerBurpSuite Extension: Log4j RCE Scanner
Python UpdatedDec 15, 2021 -
EHole Public
Forked from EdgeSecurityTeam/EHoleEHole(棱洞)3.0 重构版-红队重点攻击系统指纹探测工具
Go Apache License 2.0 UpdatedDec 15, 2021 -
JNDIExploit-1 Public
Forked from Mr-xn/JNDIExploit-1一款用于 JNDI注入 利用的工具,大量参考/引用了 Rogue JNDI 项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。(from https://github.com/feihong-cs/JNDIExploit)
Java UpdatedDec 13, 2021 -
JNDI-Exploit-Kit Public
Forked from pimps/JNDI-Exploit-KitJNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v…
Java MIT License UpdatedDec 13, 2021 -
BurpLog4j2Scan Public
Forked from mostwantedduck/BurpLog4j2ScanBurpsuite被动扫描插件
Java UpdatedDec 11, 2021 -
Apache-Log4j-Learning Public
Forked from bkfish/Apache-Log4j-LearningApache-Log4j漏洞复现笔记
-
-
nanodump Public
Forked from fortra/nanodumpDumping LSASS has never been so stealthy
C Apache License 2.0 UpdatedNov 18, 2021 -
-
-
PocOrExp_in_Github Public
Forked from ycdxsb/PocOrExp_in_Github聚合Github上已有的Poc或者Exp,CVE信息来自CVE官网。Auto Collect Poc Or Exp from Github by CVE ID.
Python MIT License UpdatedOct 28, 2021 -
Suspended-Thread-Injection Public
Forked from plackyhacker/Suspended-Thread-InjectionAnother meterpreter injection technique using C# that attempts to bypass Defender
C# UpdatedOct 20, 2021 -
InfoScraper Public
Forked from MichaelWayneLIU/InfoScraper一个基于Electron的自动化Web资产探测工具,用于渗透前期的信息搜集工作
JavaScript UpdatedOct 12, 2021 -
SysWhispers Public
Forked from jthuraisamy/SysWhispersAV/EDR evasion via direct system calls.
Assembly Apache License 2.0 UpdatedOct 12, 2021 -
-
CobaltStrikeDos Public
Forked from JamVayne/CobaltStrikeDosCVE-2021-36798 Exp: Cobalt Strike < 4.4 Dos
Python UpdatedSep 6, 2021 -